Former ransomware negotiator gets 4 years for BlackCat attacks

A former employee of a cybersecurity incident response company has been sentenced to four years in prison for his role in orchestrating BlackCat (ALPHV) ransomware attacks against U.S. companies, collecting an estimated $300 million in ransom payments from over 1,000 victims between November 2021 and September 2023.

Angelo Martino, a 41-year-old former employee of DigitalMint, was directly involved in multiple BlackCat attacks alongside accomplices Ryan Goldberg and Kevin Tyler Martin. The trio worked as affiliates of the notorious BlackCat gang, using the ALPHV ransomware to encrypt victims’ servers and demand substantial ransom payments in exchange for decryption and a promise not to leak stolen data.

The court documents reveal that Martino and his co-conspirators would often share confidential information about victims’ insurance policy limits and negotiation positions with the BlackCat operators, allowing them to extort the maximum possible amount. In one instance, Victim 1 paid a staggering $16.4 million in virtual currency after Martino provided direction and confidential information to maximize the ransom payment.

The BlackCat gang’s modus operandi is relatively straightforward: they infect victims’ systems with malware that encrypts their data, rendering it inaccessible unless a ransom is paid. In exchange for access to this extortion portal, the attackers receive a 20% share of all ransom proceeds. This lucrative business model has enabled the group to collect hundreds of millions in ransom payments from over 1,000 victims worldwide.

The indictment also highlights that Martino was not alone in his malicious activities. He worked alongside two other former DigitalMint employees, Kevin Tyler Martin and Ryan Clifford Goldberg, who were sentenced to four years in prison each in May for their role in the conspiracy. The three individuals were caught after an investigation by the FBI linked them to over 60 breaches between November 2021 and March 2022.

This case serves as a stark reminder of the importance of cybersecurity awareness and vigilance within organizations, particularly those that handle sensitive information. As the incident highlights, insider threats can have devastating consequences when left unchecked. DigitalMint CEO Jonathan Solomon condemned Martino’s actions, stating that the company had terminated both individuals immediately after discovering their misconduct.

In light of this case, security teams should take a proactive approach to threat detection and prevention by implementing regular breach and attack simulation tests. By doing so, they can identify vulnerabilities in their systems and stay one step ahead of potential attackers. As the Picus whitepaper demonstrates, these simulations can help security teams improve their incident response capabilities and prevent threats from slipping through undetected.

Ultimately, this case underscores the need for robust cybersecurity measures to protect against insider threats and sophisticated cyberattacks like those perpetrated by the BlackCat gang. By staying informed and taking proactive steps to secure our systems, we can reduce the risk of falling victim to these types of attacks.


Source: Bleeping Computer — 2026-07-10